• cyber-suite-single-tenant-v2.6.103 bd515d9278

    gandetl_admin released this 2026-09-30 10:40:35 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.103
    Built (UTC): 2026-09-30T10:39:17Z
    Source tag: v2.6.103
    Image digest: sha256:c5e62301562a13444d928c87e244edd07a9af209d702126b8bf1abe04c8ef220
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.102 (35 commits):

    Read this one first: the Review button on a gate questionnaire has never worked

    Clicking "Review", or "Review all answers", on a gate questionnaire did
    nothing at all. This affects the build you are running today.

    It matters more than a dead button. The review screen is the only route to
    "Record the decision", and a questionnaire is not saved to the project until
    that decision is recorded — the wizard says so on screen. So somebody could
    answer all forty-nine questions and have no way to keep them.

    The cause was two functions sharing a name in one file. JavaScript silently
    replaces the earlier with the later, so the questionnaire's review called the
    wrong one and failed. A guard now fails the build on any repeated function
    name, because nothing in the toolchain warned about it.

    Threats, as a place rather than a questionnaire

    The threat model has produced answers since v2.6.99. It now produces a
    register you can work. Every project gains a Threats tab with three views:

    • Threat Models — every threat model on the engagement, what has been recorded
      and what is part-answered, with Resume going straight back into the
      questions. A part-answered run says plainly that it lives in the browser it
      was started in, because it does: nothing is on the project until the
      decision is recorded.
    • Threats — the engagement's own threat register. Each threat carries a STRIDE
      category, where it came from, an owner, a status and the controls that
      address it. Threats are deliberately not scored here; an analysed threat is
      scored once, as a risk, on the Risk tab, so there is never a second answer
      to "how bad is this".
    • Trust boundaries — where something crosses between two places that trust
      each other differently, with what makes each crossing strong and what does
      not, side by side. Boundaries link to the threats that cross them and the
      controls that defend them.

    Two threat libraries to pick from

    An enterprise threat library of 141 named scenarios across fifteen domains,
    with typical actors, applicability triggers and MITRE ATT&CK, MITRE ATLAS and
    OWASP mappings. The largest domain is agentic AI and non-human identity.
    Beside it, the SCF threat catalogue's forty-one categories, natural and
    man-made.

    They are kept as two sources on purpose. SCF names categories an enterprise
    carries; the enterprise library names scenarios an attacker performs. Both are
    useful and the difference matters, so every entry says which catalogue it came
    from. Search covers names, scenarios, actors and technique ids — searching
    T1566 finds the phishing scenarios.

    Picking a threat copies it into your register, where it is yours to edit. A
    later version of a library never rewrites what an engagement recorded.

    Controls you choose, and keep

    Controls can now be picked from the library by hand, for the ones no
    generation run infers. A hand-picked control survives a scope sync: previously
    scope sync removed anything it had not derived itself, which would have
    discarded a deliberate choice.

    Every tenant's control library now carries the SCF control set. On an install
    where it had never been populated the register was simply empty, with nothing
    to scope and nothing for an assessment to count.

    Agentic AI assessment

    Three questions it was missing, each a way a well-governed agent still leaks or
    still acts on an attacker's instructions: whether retrieval is filtered to the
    person asking, what is done with what the agent produces, and how a behaviour
    change is caught when a model moves underneath you.

    Existing installs can receive them. A question set is copied into a workspace
    when it is bound, so new questions in a release previously reached nobody. The
    upgrade adds only questions your copy does not have, keeps your wording and
    order, and touches no answer already given.

    Also fixed

    • A control run interrupted by a restart no longer disables Generate Controls
      forever. A run now reports that it is alive while it works, and one that
      stops reporting is failed rather than left running indefinitely.
    • The severity bands on the inherent-risk view match the rest of the product:
      critical at 15 and above, high at 9, medium at 4. There was previously no
      critical band there at all, so a score of 20 read as "High" while the counts
      beside it called the same risk critical.
    • The assessment report downloads as an Excel workbook as well as Word.
    • "Re-run the risk profile" on the governance board lands on the triage and
      says what to do, instead of opening a page and stopping.
    Downloads